Re: If I am paranoid, should I do it?

From: Richard E. Silverman (slade@shore.net)
Date: 12/19/01

  • Next message: Kevin McMahon: "Re: PPP over SSH"

    From: slade@shore.net (Richard E. Silverman)
    Date: 19 Dec 2001 04:28:51 -0500
    
    

    >>>>> "Marcus" == Marcus <talos@algonet.se> writes:

        Marcus> I must disagree with the previous two postings... I am also
        Marcus> very paranoid and I say (in this case), If you have CPU power,
        Marcus> use it to strenghten security... If decreesing the time would
        Marcus> as someone mentioned probably make it harder to break in to
        Marcus> your system then do.

    Decreasing the regen interval will not make it "harder to break into your
    system." It's not feasible to break a server key by brute force within
    the default interval of an hour. An attacker would have to break into the
    SSH server machine *by separate means*, manage to extract the server key
    from the memory space of the running sshd -- and even then he could only
    use it to decrypt current SSH sessions, recorded since their beginning and
    started within the lifetime of that server key.

    The forward secrecy provided by the server key is about protecting
    recorded sessions from later decryption, not about host security. A
    decrypted session might reveal something that affects host security, like
    a typed password -- but your security would already have been seriously
    breached in order to obtain it in this way.

    -- 
      Richard Silverman
      slade@shore.net
    



    Relevant Pages

    • RE: [fw-wiz] The home user problem returns
      ... I've been watching with a certain morbid fascination as Marcus has ... in computer security that I do). ... -- Educating users has been proven to work at company after company. ... but my take-away from your blog article ...
      (Firewall-Wizards)
    • RE: [fw-wiz] The home user problem returns
      ... >for you, Marcus (epecially since you have, I dunno, six times the years ... >in computer security that I do). ... >100 users click evil email attachments, ... >Help desk calls, viral infections, falling victim to phishing emails, ...
      (Firewall-Wizards)
    • Re: Windows XP update problems
      ... You can subscribe to a service that will Notify you when critical security ... updates are released, Marcus. ... MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002 ... Cumulative Security update for IE7 for WinXP ...
      (microsoft.public.windowsupdate)
    • Re: [fw-wiz] concerning ~el8 / project mayhem
      ... And there are a kit of "security ... Careful Marcus, it is starting to sound like you're justifying things ... certificates titled MRCRISP (Macrus Ranum Certified Real Information ... have people calling themselves 'scientists' in the IT security ...
      (Firewall-Wizards)
    • RE: [fw-wiz] The home user problem returns
      ... "The superior man, when resting in safety, does not forget that danger ... When in a state of security he does not forget the possibility ... >for you, Marcus (epecially since you have, I dunno, six times the years ... >we set up an environment through quarantining and what-not where users ...
      (Firewall-Wizards)